Red Hat released updated Apache HTTP Server 2.4 packages for Red Hat Enterprise Linux 7 and Red Hat Software Collections 2 to remediate CVE-2015-3185. The flaw affected modules that used the obsolete ap_some_auth_required() API: when access was controlled only by a Require authorization rule, the API could incorrectly indicate that authentication was required, potentially causing an affected module to grant access that should have been denied. Apache replaced the API with ap_some_authn_required and added an ap_force_authn hook; the upstream fix shipped in Apache HTTP Server 2.4.16.
The Red Hat updates also addressed CVE-2015-3183 request smuggling caused by inconsistent chunked-transfer parsing between httpd and front-end proxies, along with WebSocket Ping denial-of-service and error-response child-process crash flaws in the Software Collections packages. Administrators should apply the updated httpd or httpd24-httpd packages; fixes were backported and installation restarts the service automatically. Red Hat Enterprise Linux 6 and earlier base httpd packages were not affected by CVE-2015-3185 because they use Apache 2.2 or 2.0.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2015:1667 for Red Hat Enterprise Linux 7, providing updated httpd packages with backported fixes for CVE-2015-3185 and CVE-2015-3183. The advisory rated the update Moderate severity and advised affected users to upgrade.
Fedora released httpd-2.4.16-1.fc21 to the Fedora 21 stable repository, incorporating the upstream fix for CVE-2015-3185.
Fedora released httpd-2.4.16-1.fc22 to the Fedora 22 stable repository, incorporating the upstream fix for CVE-2015-3185.
Red Hat later included fixes for affected Red Hat JBoss Core Services products in RHSA-2017:2708, RHSA-2017:2709, and RHSA-2017:2710.
Red Hat issued updated httpd24-httpd packages for Red Hat Software Collections 2 through RHSA-2015:1666. The update backported fixes for CVE-2015-3185 and other Apache HTTP Server vulnerabilities, and Red Hat advised users to upgrade.
Apache HTTP Server 2.4.16 became the first released upstream version to include the CVE-2015-3185 fix.
Apache replaced the obsolete ap_some_auth_required() API with ap_some_authn_required() and an ap_force_authn hook to address CVE-2015-3185. The fix was implemented in unreleased upstream versions 2.4.14 and 2.4.15.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
ubuntu.com
Open sourcerhn.redhat.com
Open sourcerhn.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.